DeadLock Adds a Hungarian Builder to Its Victim Ledger
A new victim listing points to alleged data theft at Weinberg ’93 Építő Kft., while separate technical research shows how DeadLock has leaned on unconventional infrastructure to make pressure campaigns harder to disrupt.
In ransomware cases, the file-encryption event is often only half the story. The other half is the data the operator claims to have taken, then uses as leverage. That is the context around Weinberg ’93 Építő Kft., a Hungarian construction and steel fabrication company that has been named in a DeadLock victim listing alongside an allegation of more than 650 GB of internal data.
At the time of writing, public information has not fully established the technical root cause, the complete scope of affected users, or whether downstream systems were compromised. The available information supports a risk analysis, not a definitive attribution of negligence or full breach impact.
Fast Facts
- DeadLock listed Weinberg ’93 Építő Kft. as a new victim.
- The listing alleges more than 650 GB of internal data were taken.
- The company is described as a Hungarian construction and steel fabrication business founded in 1993 and based in Sárospatak.
- Independent technical research has linked DeadLock to Polygon smart contracts used to rotate proxy infrastructure.
- No public evidence in this case confirms the initial access method or the full contents of the alleged leak.
What the claim really means
The significance here is less about a single victim page and more about the kind of information a project-based industrial firm can hold. If the allegation is accurate, the most sensitive assets would likely include contractor records, procurement details, engineering or production information, and finance data. For a construction business, that material can shape pricing, scheduling, partner relationships, and competitive position.
That is why modern ransomware cannot be judged by encryption alone. Double extortion turns internal data into bargaining material. Even where backups exist, the threat of publication can keep pressure on a target long after systems are restored.
DeadLock itself is technically interesting because separate analysis has described a smaller, less public-facing operation than the larger affiliate-driven ransomware brands. That research says the group was not tied to a known affiliate program and lacked a public leak site, while also using smart-contract-driven proxy rotation. Group-IB also observed an HTML wrapper associated with Session and AnyDesk-related workflows. None of that proves how this specific listing was produced, but it does show the kind of infrastructure defenders may have to anticipate.
For industrial organizations, the lesson is practical. Remote access tools need strict control. Backups must be offline and tested. Engineering, finance, and production networks should be segmented so one foothold does not become a full operational outage. And if a leak claim appears, validation has to come before public reaction, especially when the listing contains unverified allegations about financial misconduct.
Conclusion
The wider lesson is simple: ransomware crews increasingly treat business records as the real prize. In sectors built on contracts, schedules, and trust, the data itself can be as valuable to criminals as any encrypted server. The companies best positioned to resist are the ones that plan for both recovery and disclosure risk at the same time.
TECHCROOK
External backup drive: Use it for offline copies of important files and system images. Keep one disconnected when not backing up, and test restore procedures regularly. A simple drive is often easier to manage than always-on network storage for small teams.
WIKICROOK
- Double extortion: A ransomware tactic that combines encryption with data theft and leak threats.
- Proxy infrastructure: Relays used to hide the real location of attacker-controlled systems.
- Smart contract: Blockchain code that can store or trigger actions without a central server.
- Network segmentation: Dividing systems into zones so an intruder cannot move freely.
- Remote access tool: Software that lets users control systems from elsewhere and that attackers may abuse if poorly managed.



